Contact Us Today
We provide clear regulatory guidance that meets you where you are today.
Blog |

Medical device cybersecurity is not separate from patient safety. A vulnerability that interrupts therapy, changes device behavior, or delays diagnosis can cause clinical harm. Manufacturers need a structured way to connect cybersecurity threats with the safety risk management process.
AAMI TIR57 provides that connection. Published in 2016 and reaffirmed in 2023, this Technical Information Report explains information security risk management for a medical device in the context of ISO 14971. It remains an FDA-recognized consensus standard.
AAMI TIR57 is formally titled Principles for Medical Device Security—Risk Management. It gives manufacturers methods for identifying, evaluating, controlling, and documenting security risks throughout a medical device lifecycle.
Traditional safety analysis considers foreseeable hazards and harms. Cybersecurity adds an adversary who may deliberately search for weaknesses and adapt an attack. AAMI TIR57 addresses that behavior while connecting the analysis to safety, effectiveness, and data and systems security.
The report does not replace ISO 14971. Instead, it extends the safety risk management process by helping teams address security-specific concepts such as assets, threats, vulnerabilities, exploitability, threat actors, and security controls. This makes it useful for connected devices, Software as a Medical Device, embedded software, mobile applications, and other products whose safety or effectiveness could be affected by a cyber event.
A TIR57-informed security risk management process generally helps a manufacturer:
The analysis should be traceable. Threats and vulnerabilities should connect to security requirements, controls, verification, residual-risk conclusions, and safety-risk records. This makes the security argument easier for auditors and FDA reviewers to follow.
The principal ISO standard for risk management of medical devices is ISO 14971. It establishes a lifecycle process for identifying hazards, evaluating and controlling risks, and monitoring whether controls remain effective.
AAMI TIR57 applies information-security methods within that framework. For example, a vulnerability may permit unauthorized modification of a therapy setting. The security analysis examines the attack and controls; the safety analysis evaluates the hazardous situation and possible harm.
An integrated approach helps demonstrate that medical device security controls support overall safety and effectiveness.
Yes, but its role should be described carefully. AAMI TIR57:2016 was reaffirmed in 2023, and FDA continues to recognize it. ANSI/AAMI SW96:2023, Standard for Medical Device Security—Security Risk Management for Device Manufacturers, is a newer consensus standard that provides more formalized premarket security risk management requirements.
SW96 builds on TIR57's foundation; it does not eliminate TIR57's value. FDA's February 2026 cybersecurity guidance recommends a security risk management plan and report such as those described in both resources, with applicable outputs included in premarket submissions.
Neither voluntary consensus standard is automatically mandatory for every manufacturer. The selected standards and extent of conformity should be appropriate for the device, architecture, risk, and submission.
For postmarket activities, AAMI TIR97 addresses security risk management for marketed medical devices. Together, these resources support a lifecycle approach that continues after authorization as new vulnerabilities, exploits, components, and mitigations emerge.
Medical device security protects a device and related systems from unauthorized access, modification, disclosure, disruption, or destruction. It supports authenticity, integrity, availability, authorization, confidentiality, and secure updateability.
Security is broader than protecting health information. A cyber event may affect performance, therapy, or clinical information. Risk decisions should consider patient harm as well as technical impact.
FDA places medical devices into three risk-based classes. Class I devices are generally the lowest risk and are subject to general controls. Class II devices generally present moderate risk and are subject to general and special controls. Class III devices present the highest risk and are generally subject to Premarket Approval in addition to general controls.
Classification affects regulatory controls, but cybersecurity depends on the actual device and its risks. Manufacturers should confirm the classification regulation, product code, exemptions, and cybersecurity obligations for their product.
The Safe Medical Devices Act of 1990 strengthened oversight of marketed devices. It expanded reporting by user facilities, supported tracking and postmarket surveillance, strengthened recall authority, and refined device-class controls. Its purpose was to improve protection and help FDA learn about serious device problems more quickly.
The Act is not a cybersecurity standard, but it reinforces the broader lifecycle principle behind modern medical device risk management: safety oversight continues after a product reaches the market.
Manufacturers using AAMI TIR57 should confirm that they have:
Quality Commercial Consultants helps software-enabled medical device and SaMD sponsors prepare clear, submission-ready cybersecurity documentation. QCC supports cybersecurity risk analyses, threat-modeling summaries, SBOM documentation, lifecycle vulnerability management evidence, testing documentation, and traceability between risks, controls, and verification activities.
We provide clear regulatory guidance that meets you where you are today. Contact our team to discuss your medical device, submission timeline, and current cybersecurity documentation.
We provide clear regulatory guidance that meets you where you are today.
